Research Article

From Spatial to Spectral Domain, a New Perspective for Detecting Adversarial Examples

Algorithm 1

HLFD adversarial detection algorithm
Input:
Original samples,
Adversarial samples
The number of samples
Selected high-level representation layer
Model trained by
Output:
Detector
1For in do
2# the th feature map
3XL
4XadvL
5XLH getHighFrequencyComponent(XL)
6XadvLH getHighFrequencyComponent(XL)
7XLH_list.append(XLH.flatten())
8XadvLH_list.append(XadvLH.flatten())
9End
10Trained with XLH_list, XadvLH_list
11Return